Netskope Threat Labs

FILE-IMAGE Adobe Acrobat Pro EMF file EMFPlusPath object out of bounds read attempt

IPS-SWG

1 SID: 47892

First seen
July 2022
Last seen
October 2026

Detects a document exploiting CVE-2018-12795, CVE-2018-16014, and CVE-2018-4970, out-of-bounds reads in Adobe Acrobat's metafile path handling that can leak memory. The rule matches the crafted path records that public exploits use to read beyond allocated buffers.